The MIT license, README, tests, and release notes provide solid consumer and project documentation. A single registry maintainer, absent security policy, and unpinned workflow actions add manageable risk.
68%
Total Score
83
88
67
The package has only three releases since August 2022, with a median interval of about 660 days and one release in the last 12 months. The latest release is recent enough to show the project is not abandoned, but the cadence is slow.
There were no commits and no active maintainers in the last three months. Although a release was published recently, the lack of continuing commit activity weakens confidence in ongoing maintenance.
The repository uses Composer build tooling, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no dedicated security policy, despite the README providing a security contact. The contact helps compensate for the missing formal process, but vulnerability-reporting guidance is still limited.
The single workflow was fully analyzed with no untrusted checkout, script injection, or audit findings. However, all three action references are unpinned, leaving avoidable build reproducibility and action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
inspirum/xml Version ^3.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.